V I R T U A L P R I V A T E N E T W O R K S
Advanced VPN Configuration Options
7-32
Security Appliance User Guide
Version 3R2
7
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
A D V A N C E D V P N C O N F I G U R A T I O N O P T I O N S
Some advanced options are available, but not always required to be
configured for each tunnel. They include dead peer detection (DPD), DF
Bit settings, NAT-Traversal (NAT-T) perfect forward secrecy (PFS) and
anti-replay protection.
DEAD PEER DETECTION (DPD)
Dead Peer Detection (DPD) allows two or more VPN appliances to send
communication to determine the validity of a VPN tunnel. Without DPD a
situation could arise where communication between one or more VPN
appliances is interrupted unexpectedly, causing the VPN tunnel to not
respond or allow traffic to pass. This service interruption could last until
the SA lifetime expires, if DPD were not used. To configure DPD use the
set ike
command along with the
DPD
option to set how many missed
r-u-there message are allowed before the VPN tunnel is torn down the
rebuilt.
set ike gateway {name_str} dpd always-send
set ike gateway {name_str} dpd interval {number}
set ike gateway {name_str} dpd retry {number}
NAT-TRAVERSAL (NAT-T)
NAT-T allows encrypted VPN traffic to be encapsulated as a UDP
datagram using port 500. During phase 1 of the VPN negotiation the VPN
appliance’s will determine automatically if any device along their path
has applied NAT to the VPN packets. If NAT is applied along the specific
path the VPN appliances will then encapsulate the VPN traffic as UDP
datagrams using port 500.
To enable NAT-Traversal, use the
set ike
command.
set ike gateway {name_str} nat-traversal
PERFECT FORWARD SECRECY (PFS)
• PFS is a condition in which an encryption system changes encryption
keys often and ensures that no two sets of keys have any relation.
Unless specified all new
p2-proposal
s defined have PFS enabled. To
disable PFS you will use the
set ike
command with the
no-pfs
option,
to disable PFS for the defined
p2-proposal
.
Содержание freeGuard Blaze 2100
Страница 1: ...freeGuard Blaze 2100 User Guide Version 3R2...
Страница 14: ...I NT R O DU C T I O N About Document Conventions 1 4 Security Appliance User Guide Version 3R2 1...
Страница 24: ...G E T T IN G S T A R T E D Installing the freeGuard Blaze 2100 2 10 Security Appliance User Guide Version 3R2 2...
Страница 82: ...SY ST EM MA N AGEM E N T Using Traceroute 4 22 Security Appliance User Guide Version 3R2 4...
Страница 192: ...P OL IC Y CO NF I G URA T IO N About Schedules 9 28 Security Appliance User Guide Version 3R2 9...
Страница 216: ...P R E DEF I N E D SER V IC ES A 4 Security Appliance User Guide Version 3R2 A...